CVE-2012-6131

Roundup < 1.4.19 - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in cgi/client.py in Roundup before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the @action parameter to support/issue1.

Scores

EPSS 0.0041
EPSS Percentile 60.8%

Details

CWE
CWE-79
Status published
Products (22)
roundup-tracker/roundup < 1.4.19
roundup-tracker/roundup
roundup-tracker/roundup
roundup-tracker/roundup
roundup-tracker/roundup
roundup-tracker/roundup
roundup-tracker/roundup
roundup-tracker/roundup
roundup-tracker/roundup
roundup-tracker/roundup
... and 12 more
Published Apr 11, 2014
Tracked Since Feb 18, 2026